Energy Security: Mission Domain Intelligence Guide
Two things tell you a country is in trouble before its ministers do: how fast its gas storage is emptying, and how many tankers just went dark off its coast.
Two things tell you a country is in trouble before its ministers do: how fast its gas storage is emptying, and how many tankers just went dark off its coast.
What Energy Security covers as a mission domain
Energy security intelligence covers the availability, affordability and physical integrity of energy supply. Practitioners monitor production and refining capacity, storage levels, transmission and pipeline networks, seaborne and pipeline trade routes, and the chokepoints that concentrate risk. It also covers threats to the assets themselves: physical attacks and sabotage against substations, pipelines and terminals, drone and standoff threats to refineries, and the operational technology exposure of grid and pipeline control systems. Increasingly it includes sanctions enforcement, since a large share of the global crude trade now moves through opaque ownership and disguised logistics.
Sub-areas include supply and demand balance monitoring, critical energy infrastructure protection, chokepoint and transit risk, sanctions and shadow-fleet tracking, and transition risk covering critical minerals and grid dependency. Actor types range from state operators and national oil companies to sanctioned traders using layered shell structures, hacktivist and state-aligned groups targeting operational technology, and insurgent or criminal groups that tap pipelines for physical theft.
Why it matters
Energy is the dependency underneath every other sector. A grid failure takes water treatment, hospitals, payments and telecommunications with it, and diesel supply determines how long backup power actually lasts. Price shocks transmit into food, fertiliser and political stability within one or two quarters. For governments and operators the practical question is rarely whether an attack is possible, but how much margin exists between current supply and the point at which load shedding, rationing or emergency imports become unavoidable.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Gas storage injection rates falling behind the seasonal trajectory needed to reach normal winter start levels, visible weeks ahead in operator filings.
- Flaring volume changes detected by VIIRS Nightfire at a field or refinery, indicating outage, process upset or a shift in production routing.
- Clusters of ship-to-ship transfers in known laundering zones, paired with AIS gaps that begin and end at consistent bearings and durations.
- Repeated flag-of-convenience changes, insurance withdrawal or classification society changes across a group of similarly aged tankers.
- Unplanned outage notices and cross-border flow reversals appearing on transmission transparency platforms outside normal maintenance windows.
- Physical intrusion, gunfire damage or drone sightings reported at distribution substations, particularly repeated attempts on the same corridor.
- Spot-to-forward price spreads and regional basis blowouts that persist after weather normalises, indicating structural rather than transient scarcity.
- Recruitment or procurement activity for operational technology skills and legacy control system hardware by entities with no plausible engineering programme.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- International Energy Agency (IEA) — Oil, gas and electricity market reports, stock levels, and emergency response mechanism documentation.
- US Energy Information Administration (EIA) — Free global production, refining, trade and price series plus chokepoint volume analysis.
- ENTSO-E Transparency Platform — European electricity generation, load, cross-border flows and outage notices at hourly granularity.
- GIE AGSI+ and ALSI — European gas storage and LNG terminal inventory levels updated daily by operator.
- NOAA VIIRS Nightfire — Satellite-detected flaring and combustion sources, useful for inferring field and refinery activity.
- Global Energy Monitor — Open trackers for pipelines, LNG terminals, coal and gas plants with status, ownership and coordinates.
- OFAC, OFSI and EU consolidated sanctions lists — Designated vessels, entities and price cap guidance underpinning any shadow-fleet investigation.
- AIS providers and Sentinel-1 SAR — Vessel movement, dark-period detection and radar confirmation of ships not transmitting position.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Map the system — Diagram supply, transit and demand for the target market including single points of failure, storage, interconnection and realistic substitution options.
- Establish operating baselines — Pull multi-year storage, flow and outage series so a deviation can be judged against seasonality rather than against last week.
- Track the physical flow — Combine AIS, SAR and terminal data to follow cargoes and identify dark periods, transfers and re-routing at the vessel level.
- Assess asset threat — Review incident reporting, advisories and OT exposure for the specific operators involved, prioritising substations and compressor stations with weak redundancy.
- Quantify the margin — State how many days of cover exist under defined stress cases and identify the exact point where curtailment decisions become necessary.
- Watch the money layer — Screen counterparties, charterers and insurers against sanctions and beneficial ownership data to expose concealed trade relationships.
- Issue graded warning — Publish thresholds and named triggers so operators and policymakers act on indicator crossings rather than on narrative alone.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Energy Intelligence — Energy Production, Transport, and Markets
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Geospatial Intelligence — Intelligence Derived from Place
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
- Maritime Intelligence — Vessels, Shipping, and the Maritime Domain
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Imagery Intelligence — Interpretation of Visual Imagery
Worked in these data points
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Vessel / Ship — A maritime vessel identified by IMO, MMSI, or call sign.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
Adjacent mission domains
- Critical Infrastructure
- Sanctions Evasion
- Climate Security
- Maritime Security
- Military & Defense
- Supply Chain Security
Inside the platform: where Energy Security lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=energy— Energy Security dashboardtheater.php?d=energy— Threat theater viewdomain.php?d=mar— Vessel / Ship profilesearch.php— Company / Organization profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Energy Security:
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
- NetFlow / Traffic Anomaly — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Map the system is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Track the physical flow turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Issue graded warning feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Energy Security
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts care about energy in two directions: the fuel and power their own force depends on, and the energy systems sustaining an adversary or a partner. Work covers supply resilience for deployed operations, protection requirements for host nation grids and pipelines supporting basing, chokepoint transit risk for tankers, and assessment of refining, storage and generation resilience. Products feed force protection, logistics planning and infrastructure protection tasking. The strict constraint is directional: analysis identifies what must be defended and where redundancy is thin, and vulnerability findings on civil systems are routed to operators, national CERTs and regulators through coordinated disclosure rather than retained for any other purpose.
🕵 National intelligence
National intelligence requirements typically cover supply adequacy through a heating or cooling season, sanctions circumvention in crude and product trade, state coercion using energy dependency, and threats to critical energy infrastructure from state-aligned and criminal actors. Fusion pairs open storage and flow telemetry, which is unusually good in this domain, with liaison and financial reporting that is not. Handling matters because commercially sensitive and market-moving material appears in the same assessments as sensitive sourcing. Maintain a shareable layer for regulators, operators and allied energy ministries, and express judgments with explicit thresholds so policy customers can see what would change the assessment.
👮 Law enforcement
Law enforcement engagement covers sanctions enforcement, oil theft and pipeline tapping, fuel adulteration and smuggling, procurement fraud, and criminal or state-aligned intrusion into operational technology. Evidence is built from vessel and cargo documentation, customs records, corporate filings and financial flows, all requiring lawful process across multiple jurisdictions. Position data and imagery establishing a ship-to-ship transfer need full acquisition provenance to survive challenge. Cyber incidents at energy operators demand early forensic preservation and careful jurisdiction mapping. Charging decisions usually rest on documentary fraud, sanctions breach and money laundering rather than on the physical offence itself.
🔍 Private investigation and corporate security
Corporate security and commercial intelligence teams use this for counterparty screening, cargo and vessel due diligence, trading compliance and site protection. Work includes checking whether a counterparty fleet has dark periods or identity anomalies, whether an intermediary sits in a layered ownership structure designed to obscure origin, and whether a supply route has single points of failure. Private actors cannot access non-public government data, must not conduct surveillance on individuals, and should never attempt any interaction with control systems or networks they do not own. Sanctions concerns escalate to compliance and to the relevant authority, never to unilateral action.
📰 Journalism and OSINT media
Journalists have an unusually strong open evidence base here: storage telemetry, flow data, vessel positions and radar imagery. Verification requires reconciling reported positions with independent radar detection, checking registry and ownership records rather than relying on a single database, and dating imagery precisely. Be careful with attribution of infrastructure damage, where sabotage, accident and deferred maintenance are frequently indistinguishable in early reporting. Protect sources inside operators and trading houses, who face immediate dismissal and sometimes criminal exposure. Give companies and flag states a genuine right of reply, and avoid publishing detail that would serve as a targeting aid.
🌍 NGO, humanitarian and human rights
Humanitarian and human rights organisations engage with energy through fuel poverty, conflict-driven outages that disable hospitals and water systems, environmental and health harm from theft and flaring, and the human cost of transition in extractive communities. Documentation of attacks on energy infrastructure that disable essential civilian services can support international humanitarian law accountability work and should be preserved to that standard. Do-no-harm applies to publishing outage or weakness detail that could invite further attack. Duty of care covers staff operating near energy infrastructure in conflict, since proximity to it is itself a risk factor.
🎓 University and research
Research strengths lie in the quality of open telemetry: transmission operator platforms, storage inventories and vessel positions support genuinely reproducible work. Methodological care is needed on vessel identity resolution, where naive use of transmitted identifiers produces confident errors, and on inferring intent from dark periods, which have many benign causes. Ethics approval is usually limited but data licensing is not, since several key datasets are commercial with strict redistribution terms. Publish identity resolution rules and code, cite data vintages because operators revise historical series, and avoid publishing work that amounts to a vulnerability assessment of a named operating asset.
Playbook: working Energy Security end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the system boundary
State exactly what is being assessed: a country gas balance through winter, a refinery crude supply, a transmission corridor, or a company exposure to one strait. Energy analysis fails when the boundary is fuzzy, because imports, storage and interconnection all cross it. Identify the physical assets, commercial actors and regulator inside the boundary. A good output is a system diagram with flows, capacities and counterparties at each edge. Stop when every energy unit entering or leaving the boundary is accounted for by a named route or a documented gap.
Phase 2 — Baseline supply, storage and demand
Assemble multi-year series for production, imports, storage inventories, generation mix and demand at the highest frequency published. Establish the seasonal shape so a drawdown can be judged against the same week in prior years rather than against last month. Note which series are estimates, which are revised and how quickly. A good output is a normalised balance with storage expressed as days of cover at seasonal demand. Stop when you can state what normal looks like for this week of the year with a defensible range.
Phase 3 — Map chokepoints and redundancy
Identify points where a single failure removes disproportionate capacity: straits and canals, compressor stations, interconnectors, a small number of high voltage substations, a single import terminal. For each, establish the alternative, how long the switch takes and what capacity is lost in the process. This is the difference between a fragile and a resilient system regardless of headline capacity. A good output is a chokepoint register with substitution time and residual capacity. Stop when each chokepoint has a documented failover or an explicit statement that none exists.
Phase 4 — Track seaborne and pipeline flows
Monitor movements on the routes serving the system, reconciling vessel-reported positions with radar detection and port call records. Identify loading and discharge patterns, unusual routing, and vessels whose reported track is inconsistent with independent observation. Pipeline flows come from transmission operator telemetry where published. A good output is a flow picture with volumes by origin and a list of movements requiring further identity work. Stop when reported flows reconcile with the balance or the discrepancy is documented and quantified.
Phase 5 — Resolve identity on anomalous vessels
Where a movement looks irregular, anchor the investigation on the hull rather than the transmitted identity: IMO number, dimensions, build year, registry history, class and insurance status, management company and port state control record. Ships change name, flag and broadcast identity easily, so analysis built on transmitted identity alone will eventually be wrong in a publicly embarrassing way. A good output is an identity-resolved vessel history with sourced changes and dates. Stop when the hull is established or the ambiguity is stated plainly in the product.
Phase 6 — Assess sanctions and ownership layering
For restricted flows, trace charterer, operator, technical manager, beneficial owner and insurer through registry and corporate data, and check current designations across the applicable regimes. Look for the standard layering pattern: a newly formed manager in a permissive jurisdiction, a flag change within months of a designation, and insurance that cannot be verified. A good output is an ownership graph with dates and designation status per entity. Stop at documented ownership, and refer suspected breaches to compliance and the relevant authority.
Phase 7 — Evaluate physical protection posture
For assets inside the boundary, assess exposure to physical attack, standoff threats and insider risk at a protective level: perimeter and access control maturity, redundancy of critical transformers and long-lead spares, dependency on a single control centre, and restoration time. The purpose is to identify where investment reduces consequence. A good output is a prioritised protection gap list expressed in restoration hours avoided. Stop short of documenting exploitable weaknesses in detail, and route specifics to the operator through a controlled channel.
Phase 8 — Assess operational technology exposure defensively
Review the control system estate at the level of architecture and process: segmentation between corporate and control networks, remote access governance, vendor and integrator access, asset inventory completeness, and monitoring coverage. Use published advisories and sector alerts to map known threat activity to the environment. Findings go to the operator and the national CERT under coordinated disclosure. A good output is a defensive gap assessment mapped to a recognised control framework. Stop before any scanning, probing or interaction with systems you do not own.
Phase 9 — Build the warning indicator set
Select a small number of indicators with thresholds: storage cover below a set number of days at seasonal demand, unplanned outage duration exceeding a level, import dependence on a single route above a share, sustained flow decline on a corridor, or a rise in designated vessel activity. Each needs a data source, an update cadence and an owner. A good output is an indicator table wired to the decisions that would follow. Stop when every indicator would change somebody's behaviour if it fired.
Phase 10 — Report with thresholds and route findings correctly
Publish assessments stating the balance, the binding constraint, the indicators being watched and what would change the judgment. Route vulnerability findings on real assets to the operator, sector regulator and national CERT rather than into a public product, and record the disclosure timeline. Separate market-sensitive content and control access to it. A good output is a product a policy customer can act on plus a documented disclosure trail for anything protective. Stop when nothing published would help an attacker choose a target.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| International Energy Agency | Open | Oil, gas, coal and electricity market reports, member country stock data and medium-term outlooks with methodology notes. | Authoritative demand and supply balance framing and the reference point for stock adequacy discussions. |
| US Energy Information Administration | Open | Weekly and monthly production, stocks, refinery runs and trade data plus global outlooks and country analysis briefs. | High-frequency free series for balance work and a widely accepted benchmark for cross-checking other estimates. |
| ENTSO-E Transparency Platform | Registration | European electricity generation, load, cross-border flow, outage and capacity data at hourly or better resolution by bidding zone. | Detects unplanned outages, import dependence and stress on interconnection during demand peaks. |
| Gas Infrastructure Europe AGSI and ALSI | Open | European gas storage inventories and LNG terminal send-out and inventory data updated daily by facility. | Converts storage into days of cover and detects drawdown rates diverging from seasonal norms. |
| Copernicus Sentinel-1 SAR via the Data Space Ecosystem | Registration | All-weather radar imagery detecting vessels and structures regardless of cloud or darkness on a regular revisit cycle. | Independently detects vessels whose transmitted position is absent or inconsistent, including transfer rendezvous. |
| Earth Observation Group nighttime lights and Nightfire | Open | Detections of combustion sources including gas flares, plus nighttime lights products with radiant intensity estimates. | Infers production and refining activity where reporting is absent, and detects outages through lighting loss. |
| Global Energy Monitor trackers | Open | Asset-level databases of power plants, pipelines, LNG terminals, coal mines and transmission projects with status and capacity. | Builds the physical asset register that flow and outage analysis is mapped onto. |
| OFAC sanctions programmes and SDN list | Open | US designations of entities, individuals and vessels with identifiers including IMO numbers, plus general licences and guidance. | Primary screen for vessel, owner and counterparty designation status in energy trade analysis. |
| EU Sanctions Map | Open | Consolidated presentation of EU restrictive measures by regime with listed persons, entities and sectoral restrictions. | Establishes European restriction status where US and EU designations diverge, which is common in energy trade. |
| IMO GISIS | Registration | Ship particulars, registered owner and company records, port state control and casualty modules maintained by member states. | Anchors vessel identity to hull and company records when transmitted identity is unreliable. |
| Equasis | Registration | Aggregated ship safety, ownership, management, classification and inspection data drawn from multiple authoritative sources. | Reveals management and ownership changes that typically precede participation in sanctioned trade. |
| CISA advisories and industrial control system alerts | Open | Advisories on control system vulnerabilities and threat activity affecting energy and other critical infrastructure sectors. | Maps published threat activity and vulnerable product families to the defended estate for prioritisation. |
| ENISA threat landscape reporting | Open | European analysis of threat trends including sector-specific reporting on energy and critical infrastructure. | Provides the European regulatory and threat framing that sits alongside operator obligations under NIS2. |
| Joint Organisations Data Initiative | Open | Country-reported oil and gas production, demand, trade and stock statistics submitted monthly by participating states. | Cross-checks production estimates and exposes divergence between self-reported and independently assessed output. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Energy Security. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- QGIS — Maps assets, corridors and outage geography against population and demand. Strong spatially, no help with time series or market logic.
- Python with pandas — Balance construction, storage cover calculation and anomaly detection over high-frequency operator data. Reproducibility depends on pinning revised series vintages.
- AIS visualisation platforms — Track vessel movement, port calls and loitering behaviour. Coverage gaps offshore and the ease of falsifying transmitted identity are the core limitations.
- Sentinel Hub and SAR viewers — Independent radar detection of vessels and infrastructure regardless of weather. Revisit intervals mean absence of detection proves very little.
- OpenCorporates and registry search — Resolves managers, charterers and owners behind trading entities. Jurisdictional coverage is uneven and beneficial ownership is often out of reach.
- Sanctions screening tooling — Automated matching of entities and vessels against consolidated lists. Transliteration and identifier gaps generate both false positives and genuine misses.
- Grafana — Threshold monitoring over storage, flow and outage feeds with alerting. Useful operationally, but dashboards drift out of calibration without scheduled review.
- MISP or OpenCTI — Structured sharing of threat indicators with sector partners and CERTs. Value depends entirely on the quality of the community feeding it.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Express storage as days of cover at seasonal demand, never as a percentage full. Percentages hide the fact that the same inventory means three weeks in a cold January and three months in a mild April.
- Anchor every vessel judgment on the hull. Names, flags and transmitted identifiers change in days, so identity work built on broadcast data alone produces confident findings that collapse under scrutiny.
- A dark period is a question, not an answer. Equipment failure, coverage gaps and routine operations account for most of them, so require independent radar detection or a port call reconciliation before calling concealment.
- Outage data is where grid stress becomes visible before prices react. Unplanned outage duration and the number of simultaneous units offline in one zone say more about system margin than installed capacity ever will.
- Sanctions divergence is a feature of the landscape, not an error. The same cargo can be lawful under one regime and prohibited under another, so always state which jurisdiction a finding applies to.
- Attribution of infrastructure damage should default to unresolved. Sabotage, accident, deferred maintenance and weather look identical in the first forty-eight hours, and early attribution errors in this domain are politically expensive.
- Route vulnerability findings through operators, CERTs and regulators with a documented disclosure timeline. Publishing asset-specific weaknesses helps only the attacker and destroys the operator relationships that give you access.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Energy Security is producing anything, and they are worth baselining before you change process or tooling.
- Lead time between a storage or flow indicator crossing its threshold and the operational decision it was designed to inform.
- Proportion of anomalous vessel movements resolved to a hull identity rather than left at transmitted identity level.
- Number of vulnerability findings routed through coordinated disclosure with documented operator and national CERT acknowledgement of receipt.
- Accuracy of seasonal supply adequacy calls, scored against outturn and reviewed after each heating or cooling season.
- Share of monitored chokepoints with a documented failover route, substitution time and residual capacity figure.
- Time from a sector advisory publication to a completed applicability review against the defended asset inventory.
- Proportion of early incident products that avoided attribution language later contradicted by the official finding.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Price is a lagging and noisy indicator. Physical storage, flow and outage data lead it by days to weeks.
- Nameplate capacity is not deliverable capacity; derating, maintenance and fuel constraints routinely remove a fifth of headline numbers.
- AIS gaps are not proof of wrongdoing. Coverage holes, equipment failure and legitimate transits produce identical silence.
- Announced infrastructure projects slip by years, so treating planned interconnectors as available supply overstates resilience badly.
- Grid and pipeline data is often published by parties with a commercial interest in the tightness narrative they describe.
- Attributing a substation outage to sabotage before engineering assessment is the fastest way to burn credibility with operators.
Legal and ethical considerations
Detail about critical energy infrastructure is dual-use by definition. Report vulnerability at a level that supports protective decisions without producing a targeting aid, and follow coordinated disclosure with the operator and national CERT when operational technology weaknesses are identified. Sanctions research must distinguish designated entities from those merely adjacent, since misidentification carries real commercial and legal consequences. Much market data is licensed and non-redistributable, so track provenance and honour terms before any onward sharing.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Energy Security, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
A tanker went dark. Is that evidence of sanctions evasion?
By itself, no. Transponders fail, coverage over open ocean is patchy, some areas have poor satellite reception, and crews switch equipment off for reasons that include piracy risk. A dark period becomes meaningful when it recurs on the same route, coincides with a rendezvous detected independently by radar, is followed by an unexplained draught change or port call pattern, or is combined with identity anomalies such as a recent flag change and an unverifiable insurer. Build the case from at least two independent observation types and state the alternative explanations you tested.
How should storage levels be reported?
As days of cover at the relevant seasonal demand, with the historical range for the same calendar week alongside. Percentage full is the most commonly quoted and least useful figure, because it ignores demand: eighty percent in mid-November means something entirely different from eighty percent in March. Show the drawdown rate over recent weeks, compare it to prior years, and state the weather assumption behind the demand figure. If assessing adequacy, name the specific temperature or outage scenario under which cover becomes binding, and identify what the system does when it does.
We found a vulnerability in an energy operator's exposed system. What now?
Coordinated disclosure, immediately and only. Contact the operator through a published security contact, notify the national CERT or sector regulator in parallel where the jurisdiction supports it, and record the timeline of every contact. Do not probe further, do not test the finding, do not publish technical detail, and do not include it in a client or public product while it remains live. If the operator is unresponsive, escalate through the regulator rather than through publication. The professional standard here is protective: the value of the finding is that it gets fixed, not that it gets reported first.
Can open data really assess grid stress?
In regions with transparent transmission operators, yes, and to a surprising depth. Hourly generation by type, load, cross-border flows and unplanned outage notifications together show margin, import dependence and where a zone is one unit away from difficulty. Elsewhere you fall back on nighttime lights, flaring detections, published dispatch schedules and reported curtailments, which give direction rather than precision. State which regime you are in, because a transparent-operator assessment and an inference-based assessment for an opaque system deserve very different confidence language even when they reach similar conclusions.
How do I tell sabotage from failure?
Usually you cannot, quickly, and saying so is the correct professional answer in the first days. Discriminators accumulate later: damage geometry and whether it is consistent with internal overpressure or external force, simultaneity across separated assets, maintenance history and deferred work orders, weather and seabed conditions, the presence of vessels or aircraft nearby, and eventually forensic examination. Early attribution in this domain is politically consequential and frequently wrong. Publish what is observed, list the hypotheses, state what evidence would discriminate between them, and update when the physical investigation reports.
Which sanctions list governs a given cargo?
Potentially several, and they diverge. US, EU, UK and other regimes designate different entities, apply different ownership thresholds and issue different general licences and wind-down periods, so the same shipment can be compliant in one jurisdiction and prohibited in another depending on nexus, ownership, insurance and payment currency. Establish the nexus first: where the parties are incorporated, where payment clears, whose insurance and whose vessels are involved. Then screen against each applicable list and state findings jurisdiction by jurisdiction. Never publish a single sanctioned or not sanctioned verdict without naming the regime.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- NIS2 Directive and equivalent national critical infrastructure regimes, which set security and incident reporting duties for energy operators.
- IEC 62443 series on industrial automation and control system security, which defines the zone and conduit model used in operational technology assessment.
- NERC Critical Infrastructure Protection standards, which govern bulk electric system security obligations in North America.
- ISO 27001 and the NIST Cybersecurity Framework, which provide the management system and control framing used in operator gap assessments.
- Coordinated vulnerability disclosure practice under ISO 29147 and ISO 30111, which governs how a vulnerability finding is reported and remediated.
- OFAC, OFSI and EU restrictive measures regimes, which define designation, ownership control tests and licensing for energy trade.
- IEA emergency response mechanism and member stockholding obligations, which frame what supply adequacy means in policy terms.
- IMO ship identification and safety instruments, which underpin the hull-based identity resolution used in seaborne trade analysis.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Oil, gas and electricity market reports — International Energy Agency. Regular market balance analysis and medium-term outlooks
- Petroleum and electricity data series — US Energy Information Administration. High-frequency open production, stock and trade statistics
- Transparency Platform — ENTSO-E. European electricity generation, load, flow and outage data at hourly resolution
- Aggregated Gas Storage and LNG inventories — Gas Infrastructure Europe. Daily facility-level gas storage and LNG terminal data for Europe
- Specially Designated Nationals list and sanctions programmes — US Department of the Treasury Office of Foreign Assets Control. Designations including vessels identified by IMO number
- Industrial control system advisories — US Cybersecurity and Infrastructure Security Agency. Advisories on control system vulnerabilities and threat activity in energy
- Threat Landscape reporting — European Union Agency for Cybersecurity. Annual and sectoral analysis of threats to critical infrastructure
- Global energy infrastructure trackers — Global Energy Monitor. Asset-level datasets of plants, pipelines and terminals with status and capacity
- World Energy Statistics — Joint Organisations Data Initiative. Country-reported oil and gas production, demand and stock statistics
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: storage and flow baselines, dark-fleet tracking and threshold-based warning on the assets and corridors that carry your supply. Explore the platform, or browse the rest of the library by following any tag above.